Insecure Exposure of Plaintext Passwords in Debug Logs
CVSSv3 Score: 3.8
A Cleartext Storage of Sensitive Information vulnerability in FortiMail, FortiVoice and FortiRecorder debug logs may allow an...
Path traversal vulnerability in FortiSOAR Agent Connector Bridge server
CVSSv3 Score: 5.5
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FortiSOAR Agent Connector...
Authentication rate-limit bypass permits to brute force admin logins
CVSSv3 Score: 7.3
An Improper Control of Interaction Frequency vulnerability in FortiWeb may allow a remote unauthenticated attacker to bypass...
Protected hostname bypass
CVSSv3 Score: 5.0
An authentication bypass by spoofing vulnerability in FortiWeb protected hostname feature may allow a remote unauthenticated attacker...
Authentication Lockout Bypass via Race Condition
CVSSv3 Score: 3.4
An improper restriction of excessive authentication attempts vulnerability in FortiManager and FortiAnalyzer may allow an attacker to...
OS Command injection in FortiWeb API
CVSSv3 Score: 6.7
An OS Command Injection vulnerability in FortiWeb API may allow an authenticated attacked to execute arbitrary commands...
Null Pointer Dereference in Anti-Defacement feature
CVSSv3 Score: 2.5
A NULL Pointer Dereference vulnerability in FortiWeb may allow an authenticated attacker to crash the HTTP daemon...
Format string vulnerability in fazsvcd
CVSSv3 Score: 6.5
A use of externally-controlled format string vulnerability in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud fazsvcd daemon...
Local privilege escalation via improper symlink following
CVSSv3 Score: 7.4
A UNIX symbolic link (Symlink) Following vulnerability in FortiClientLinux may allow a local and unprivileged user to...





